Brian Johnson

7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

Author

Brian Johnson

Category

Technology

Podcast website

7MinSec.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

7MS #479: A Prelude to PwnTown 06.08.2021

Hey friends, today we're talking about a new security training offering 7MinSec has created called  Light Pentest LITE - Live Interactive Training Experience . It's a 3-day course (with each class session being 3 hours long) consisting of live (via Zoom), hands-on, instructor-led sessions that are focused on teaching you how to find, exploit and defend against common Active Directory weaknesses! C...

7MS #478: Password Cracking in the Cloud - Part 4 29.07.2021

Hey friends, today we're continuing our discussion of password cracking by sharing some methodology that has helped us get a high cred yield, and some tips on taking cracked passwords from multiple sources and Frankensteining them into a beautiful report for your customer. For some background, when 7MS started as a biz, we used to crack passwords in  Paperspace  but invested in an  on-prem crackin...

7MS #477: Cobalt Strike for Newbs 21.07.2021

Today we're talking about Cobalt Strike for newbs - including how to get it up and running, as well as some tools that will help you generate beacons while evading EDR at the same time! Some helpful things mentioned in today's episode: Wherever you spin up your CS instance, it's probably a good idea to lock down the firewall to only specific IPs. With Digital Ocean, I found  this article  helpful....

7MS #476: Tales of Pentest Pwnage - Part 28 16.07.2021

**STOP!** If you didn't listen to [last week's episode](https://7ms.us/7ms-475-tales-of-internal-network-pentest-pwnage-part-27/) you might want to, since this was a two-part tale of pwnage. Either way I'll get you up to speed and talk about why this was (of course) one of my favorite pentests ever.

7MS #475: Tales of Internal Network Pentest Pwnage - Part 27 08.07.2021

Yeahhhhhh! Today's another fun tale of pentest pwnage, including: The importance of starting your pentest with an AD account that actually has access to...ya know...stuff The importance of starting your pentest plugged into a network that actually has...you know...systems connected to it! This BHIS article  is awesome for finding treasures in SMB shares PowerUpSQL audits are a powerful way to get...

7MS #474: Password Cracking in the Cloud - Part 3 30.06.2021

Hey friends! Today we're dusting off an old mini-series about password cracking in the cloud (check out  part 1  and  part 2 ) and sharing some awesome info on building a monster of a cracking rig in AWS! One reason we haven't talked about password cracking in the cloud in a while is because back in winter of 2019 I built  baby's first password cracking . Unfortunately, this week, Hashy (the name...

7MS #473: Interview with Nikhil Mittal 24.06.2021

Hey everybody! Today  Joe  and I sat down with  Nikhil Mittal  of  Pentester Academy  and  Altered Security  to talk about a whole slew of fun security topics: How Nikhil first got involved in Pentester Academy Nikhil's hacker origin story How does Nikhil feel about his tools being used by baddies? What security tools/defenses would be good for SMBs to focus on? Active Directory security - is all...

7MS #473: Interview with Nikhil Mittal 24.06.2021

Hey everybody! Today  Joe  and I sat down with  Nikhil Mittal  of  Pentester Academy  and  Altered Security  to talk about a whole slew of fun security topics: How Nikhil first got involved in Pentester Academy Nikhil's hacker origin story How does Nikhil feel about his tools being used by baddies? What security tools/defenses would be good for SMBs to focus on? Active Directory security - is all...

7MS #472: Interview with Christopher Fielder 16.06.2021

Today our good pal Christopher Fielder from  Arctic Wolf  is back for an interview  three-peat ! He joins Joe "The Machine" Skeen (a.k.a.  Gh0sthax ) and I to talk about all things ransomware, including: How the Colonial Pipeline incident may have started  from a weak VPN cred with no MFA . Silver lining (?) - they  got some of the $ back . Was the federal government's response good enough? What ...

7MS #471: Cyber News - Ransomware Should Run Somewhere Edition 09.06.2021

Hey everybody, happy June! Our pal  Joe  is back to cover some great security stories with us, including: Peloton's leaky API Some Colonial Pipeline discussion ( story 1 ,  story 2 ) Amazon Sidewalk   doesn't  really share your Internet connection with neighbors/strangers. The  Hacker News article  doesn't do an awesome job of clearing that up either.  

7MS #470: First Impressions of Meraki Networking Gear 02.06.2021

Today we're doing something new - a  first impressions  episode of Meraki networking gear. Note: this is  not  a sponsored episode, but rather a follow up to  episode #460  where I talked about throwing all my UniFi gear into the ocean and replacing it with Meraki gear. At the end of that episode I asked if anybody was interested in a "first impressions" of the gear, and it turns out (at least 6)...

7MS #469: Interview with Philippe Humeau of CrowdSec 26.05.2021

Hey friends! Today we're talking with Philippe Humeau, CEO of  CrowdSec , which is " an open-source massively multiplayer firewall able to analyze visitor behavior & provide an adapted response to all kinds of attacks. It also leverages the crowd power to generate a global IP reputation database to protect the user network ." I came into this interview not knowing much at all about CrowdSec, so I...

7MS #468: Eating the Security Dog Food - Part 3 20.05.2021

Today we continue the series on  eating your own security dog food ! Specifically, we talk about: Keeping a log and procedure for sanitizing systems Keeping a log and procedure for  provisioning  systems A big "gotcha" to be aware of when using Windows system dropboxes - make sure your Windows user account doesn't expire, because Splashtop doesn't have any way to update it! To prevent this, set th...

7MS #467: How to Succeed in Business Without Really Crying - Part 9 12.05.2021

Hey everybody! I stayed in a hotel for the first time in over a year and boy oh boy...I hope I didn't get COVID from the bedsheets! Anyhow, on that journey I thought of some things that I think will help your business on the marketing/project management/sales side to be more successful and less annoying. DISCLAIMER: I have no formal training in these areas, but I've been on both sides of the table...

7MS #466: Attacking and Defending Azure AD Cloud (CARTP) 05.05.2021

Welp, I need another security certification like I needed a bunch to the retinas, but even after all the fun (and pain) of  CRTP  I couldn't help but sign up for the maiden voyage of  Attacking and Defending Azure AD Cloud - a.k.a. CARTP . This cert comes to us from our friends over at  Pentester Academy , and is all about pwning things in Azure AD which is mostly new ground for me. I this episode...

7MS #465: Cyber News - The FBI Might Be Getting Into the IR Biz Edition 28.04.2021

Hey friends!  Today Joe "The Machine" Skeen (a.k.a.  Gh0sthax ) and I talk about some of our favorite news stories, including: FBI removes hacker back doors NSA: 5 security bugs under active nation-state cyberattack Ubiquiti is accused of covering up a 'catastrophic' data breach — and it's not denying it .  On a side note, enjoy our podcast about how we lost our love for Ubiquiti a while back:  7M...

7MS #464: Interview with Christopher Fielder of Arctic Wolf 22.04.2021

Today our friend Christopher Fielder of Arctic Wolf joins us on the show again (check out his first appearance in  episode #444  - this time to talk about the security journey, and how to start out in your "security diapers" and mature towards a stronger infosec program. Specifically, we talk about: When the company has  one  person in charge of IT/security, how can you start taking security serio...

7MS #463: DIY Pentest Dropbox Tips - Part 5 14.04.2021

In the last two episodes of this series ( #449  and  #450 ) we've been diving into how to not only speed up the process of spinning up a DIY pentest dropbox, but how to  automate  nearly the entire build process! In today's episode we talk specifically about how to streamline the Windows 10 build process. As previously mentioned,  this article  is awesome for creating a core Win 10 answer file tha...

7MS #462: Pentesting with the Hak5 Key Croc 07.04.2021

Today we talk through our first engagement using  Hak5 Key Croc  to steal and exfil data. In the past, my internal monologue when a new Hak5 toy is released sounds like this: "I certainly don't need another Hak5 doo-dad! The last one didn't ever work that great, and ended up in a drawer full of past Hak5 doo-dads that didn't work that great." "Whaaaaat? A new cool and hip video for the INSERT_CATC...

7MS #461: Tales of Internal Network Pentest Pwnage - Part 26 31.03.2021

OK I probably say this every time, but I'm gonna say it again: this tale of pwnage is my one of my favs - and not because of the tools/tradecraft, but because of  why  the company needed our help in the first place. I think I'd file this under the category of "rescue and recovery mission" more than a pentest, but it was a total blast. I also cover a few tangents, including how COVID shot #2 gave m...

7MS #460: Why I'm Throwing My UniFi Gear Into the Ocean 24.03.2021

Hey friends!  Warning: this is not a "typical" 7MS episode  where we try hard to deliver  some  level of security value. Instead, today is a big, fat, crybaby, first-world problems whine-fest about how I  used  to love my  UniFi  gear for many years, but then a few weeks ago I hit unhealthy levels of rage while working with it...and subsequently completely ripped it all out of the wall and threw i...

7MS #459: Cyber News - Microsoft Exchange Makes the World Cry Edition 17.03.2021

Happy mid-March! Our good pal  Gh0sthax  joins us today for another hot dish of cyber news! Stories include: Microsoft Exchange cyber attack  - Hacker News has a nice  what we know so far  story, but things have evolved  really  fast, so make sure you check Microsoft's  primary advisory , the  script to run on local servers  and newer updates such as the recent  one-click remediation for unsupport...

7MS #458: Interview with Tanya Janca 11.03.2021

Today we're super excited to share a featured interview with Tanya Janca of  WeHackPurple ! Tanya has been in software development from the moment she was of legal age to work in Canada - beginning by working with some huge companies (Nokia/Adobe) before falling in love with application security and eventually starting a company of her own.   Gh0sthax  and I sat down with Tanya over Zoom to discus...

7MS #457: Tales of Internal Network Pentest Pwnage - Part 25 04.03.2021

Hi! This episode of pentest pwnage is a fun one because it was built for  speeeeeeeeeeeeeeeed . Here's some of the things we're doing/running when time is of the essence: Get a cmd.exe spun up in the context of your AD user account: runas /netonly /user:samplecompany\billybob "C:\windows\system32\cmd.exe" Then get some important info in  PowerView : Get-DomainUser -PreAuthNotRequired  - find AD us...

7MS #456: Certified Red Team Professional - Part 4 25.02.2021

Hello friends!  Today, Joe ( Gh0sthax ) and I complete our series on  CRTP - Certified Red Team Professional  - a really awesome pentesting training and exam based squarely on Microsoft tools and tradecraft.  Specifically, Joe and I talk about: We  don't  think the training/exam is for beginners, despite how its advertised Both the lab PDF and PowerPoint have their own quirks - which may ultimatel...

Listen to the 7 Minute Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.